<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Fortinet</title><description>Cybersecurity articles tagged #Fortinet on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Gunra Ransomware Exploits Fortinet Flaws and Bypasses MFA</title><link>https://runtimerebel.com/blog/gunra-ransomware-exploits-fortinet-flaws-and-bypasses-mfa</link><guid isPermaLink="true">https://runtimerebel.com/blog/gunra-ransomware-exploits-fortinet-flaws-and-bypasses-mfa</guid><description>Gunra ransomware targets critical infrastructure using leaked Conti code, old Fortinet vulnerabilities, and MFA bypass techniques.</description><pubDate>Wed, 12 Aug 2026 09:05:47 GMT</pubDate><category>Ransomware</category><category>Fortinet</category><category>Credential Theft</category><category>Critical Infrastructure</category></item><item><title>Hackers Breach Polish CHP Plant via Private APN and Teltonika Router</title><link>https://runtimerebel.com/blog/hackers-breach-polish-chp-plant-via-private-apn-and-teltonika-router</link><guid isPermaLink="true">https://runtimerebel.com/blog/hackers-breach-polish-chp-plant-via-private-apn-and-teltonika-router</guid><description>Attackers breached a Polish combined heat and power plant via a private APN, shutting down a steam turbine and water treatment system.</description><pubDate>Tue, 11 Aug 2026 08:44:42 GMT</pubDate><category>Critical Infrastructure</category><category>Ransomware</category><category>Fortinet</category><category>Teltonika</category><category>Siemens</category></item><item><title>CVE-2025-68686: Fortinet FortiOS Patch Bypass for Post-Exploit Persistence</title><link>https://runtimerebel.com/blog/cve-2025-68686-fortinet-fortios-patch-bypass-for-post-exploit-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-68686-fortinet-fortios-patch-bypass-for-post-exploit-persistence</guid><description>CISA warns of active exploitation of CVE-2025-68686 in Fortinet FortiOS, allowing attackers to bypass a patch for post-exploit persistence and expose sensitive data.</description><pubDate>Fri, 31 Jul 2026 10:43:21 GMT</pubDate><category>CVE-2025-68686</category><category>Fortinet</category><category>Fortios</category><category>Information Exposure</category><category>Patch Bypass</category><category>Post Exploitation</category><category>CISA KEV</category><category>CWE-200</category></item><item><title>Lynx Ransomware Linked to Massive FortiBleed Credential Theft</title><link>https://runtimerebel.com/blog/lynx-ransomware-linked-to-massive-fortibleed-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/lynx-ransomware-linked-to-massive-fortibleed-credential-theft</guid><description>Threat actors behind Lynx and INC ransomware leverage FortiBleed campaign to harvest over 440,000 Fortinet VPN credentials via CVE-2023-48788 exploits.</description><pubDate>Thu, 02 Jul 2026 07:36:16 GMT</pubDate><category>Lynx Ransomware</category><category>INC Ransomware</category><category>CVE-2023-48788</category><category>Fortinet</category><category>Credential Theft</category><category>FortiClient EMS</category></item><item><title>Fortinet FortiBleed Campaign: 86,000+ VPN Credentials Stolen</title><link>https://runtimerebel.com/blog/fortinet-fortibleed-campaign-86000-vpn-credentials-stolen</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortinet-fortibleed-campaign-86000-vpn-credentials-stolen</guid><description>Fortinet addresses the FortiBleed campaign involving 86,000+ confirmed working credentials. Technical analysis and mitigation steps for security professionals.</description><pubDate>Mon, 22 Jun 2026 10:16:29 GMT</pubDate><category>Fortinet</category><category>Fortios</category><category>FortiBleed</category><category>Credential Harvesting</category><category>VPN Security</category></item><item><title>FortiBleed: 73,932 FortiGate Systems Exposed – Credential Leak Analysis</title><link>https://runtimerebel.com/blog/fortibleed-73932-fortigate-systems-exposed-credential-leak-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortibleed-73932-fortigate-systems-exposed-credential-leak-analysis</guid><description>Analysis of the FortiBleed campaign, detailing the exposure of administrative and VPN credentials for over 73,000 Fortinet FortiGate firewalls and critical mitigation…</description><pubDate>Sat, 20 Jun 2026 05:36:54 GMT</pubDate><category>FortiBleed</category><category>FortiGate</category><category>Fortinet</category><category>Credential Exposure</category><category>Firewall Security</category><category>Network Security</category></item><item><title>FortiBleed Data Leak: Securing Fortinet VPNs Against Exposure</title><link>https://runtimerebel.com/blog/fortibleed-data-leak-securing-fortinet-vpns-against-exposure</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortibleed-data-leak-securing-fortinet-vpns-against-exposure</guid><description>CISA warns organizations after 74,000 Fortinet VPN credentials were leaked online. Learn how to mitigate the FortiBleed threat and secure your network.</description><pubDate>Fri, 19 Jun 2026 09:44:30 GMT</pubDate><category>Fortinet</category><category>FortiGate</category><category>VPN</category><category>CVE-2018-13379</category><category>CISA</category><category>Credential Leak</category></item><item><title>FortiBleed: 73,000 Fortinet VPN Credentials Exposed</title><link>https://runtimerebel.com/blog/fortibleed-73000-fortinet-vpn-credentials-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortibleed-73000-fortinet-vpn-credentials-exposed</guid><description>FortiBleed leak compromises Fortinet and FortiGate VPN credentials for over 73,000 firewall URLs globally, posing significant access risks.</description><pubDate>Thu, 18 Jun 2026 01:08:29 GMT</pubDate><category>FortiBleed</category><category>Fortinet</category><category>FortiGate</category><category>VPN</category><category>Credentials</category><category>Data Leak</category></item><item><title>Credential Harvesting Heist Compromises 30K+ Fortinet Devices</title><link>https://runtimerebel.com/blog/credential-harvesting-heist-compromises-30k-fortinet-devices</link><guid isPermaLink="true">https://runtimerebel.com/blog/credential-harvesting-heist-compromises-30k-fortinet-devices</guid><description>A widespread credential harvesting campaign has compromised over 30,000 Fortinet devices across 200 countries, enabling unauthorized access for threat actors.</description><pubDate>Wed, 17 Jun 2026 13:29:46 GMT</pubDate><category>Fortinet</category><category>Credential Harvesting</category><category>Cyberattack</category><category>Data Breach</category></item><item><title>Fortinet FortiSandbox: Attackers Exploit CVE-2026-39813, -39808, -25089</title><link>https://runtimerebel.com/blog/fortinet-fortisandbox-attackers-exploit-cve-2026-39813-39808-25089</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortinet-fortisandbox-attackers-exploit-cve-2026-39813-39808-25089</guid><description>Critical Fortinet FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are under active exploitation. Patch immediately.</description><pubDate>Tue, 16 Jun 2026 13:57:36 GMT</pubDate><category>Fortinet</category><category>FortiSandbox</category><category>CVE-2026-39813</category><category>CVE-2026-39808</category><category>CVE-2026-25089</category><category>Path Traversal</category><category>Active Exploitation</category></item><item><title>FortiSandbox RCE via CVE-2024-23108 and CVE-2024-23109 — Patch Now</title><link>https://runtimerebel.com/blog/fortisandbox-rce-via-cve-2024-23108-and-cve-2024-23109-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortisandbox-rce-via-cve-2024-23108-and-cve-2024-23109-patch-now</guid><description>Unauthenticated attackers are exploiting critical command injection flaws in Fortinet FortiSandbox to achieve RCE. Apply security updates immediately.</description><pubDate>Tue, 16 Jun 2026 09:58:32 GMT</pubDate><category>CVE-2024-23108</category><category>CVE-2024-23109</category><category>Fortinet</category><category>FortiSandbox</category><category>RCE</category><category>Command Injection</category></item><item><title>FortiSIEM RCE via CVE-2024-23108: Technical Mitigation Guide</title><link>https://runtimerebel.com/blog/fortisiem-rce-via-cve-2024-23108-technical-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortisiem-rce-via-cve-2024-23108-technical-mitigation-guide</guid><description>Analysis of critical RCE vulnerabilities CVE-2024-23108 and CVE-2024-23109 in Fortinet FortiSIEM, including detection methods and remediation steps.</description><pubDate>Mon, 15 Jun 2026 05:54:57 GMT</pubDate><category>CVE-2024-23108</category><category>CVE-2024-23109</category><category>Fortinet</category><category>FortiSIEM</category><category>RCE</category></item><item><title>FortiSandbox Command Injection (CVE-2026-25089) &amp; Critical Vendor Patches</title><link>https://runtimerebel.com/blog/fortisandbox-command-injection-cve-2026-25089-critical-vendor-patches</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortisandbox-command-injection-cve-2026-25089-critical-vendor-patches</guid><description>Critical patches from Fortinet, Ivanti, and SAP address vulnerabilities including CVE-2026-25089 (FortiSandbox command injection), enabling RCE and info disclosure.</description><pubDate>Wed, 10 Jun 2026 17:14:48 GMT</pubDate><category>CVE-2026-25089</category><category>FortiSandbox</category><category>Fortinet</category><category>Ivanti</category><category>SAP</category><category>Command Injection</category><category>RCE</category><category>Vulnerability Management</category></item><item><title>CVE-2026-35616: FortiClient EMS Exploit Delivers EKZ Infostealer</title><link>https://runtimerebel.com/blog/cve-2026-35616-forticlient-ems-exploit-delivers-ekz-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-35616-forticlient-ems-exploit-delivers-ekz-infostealer</guid><description>Attackers are actively exploiting CVE-2026-35616, an authentication bypass in FortiClient EMS, to deploy the EKZ infostealer. Protect your organization now.</description><pubDate>Thu, 28 May 2026 20:53:31 GMT</pubDate><category>CVE-2026-35616</category><category>FortiClient EMS</category><category>EKZ Infostealer</category><category>Authentication Bypass</category><category>Credential Stealer</category><category>Fortinet</category></item><item><title>CVE-2023-48788: Critical FortiClient EMS RCE Under Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2023-48788-critical-forticlient-ems-rce-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-48788-critical-forticlient-ems-rce-under-active-exploitation</guid><description>Exploitation of CVE-2023-48788 in FortiClient EMS allows unauthenticated remote code execution. Administrators must patch to version 7.2.3 or 7.0.11 immediately.</description><pubDate>Thu, 28 May 2026 13:26:51 GMT</pubDate><category>Fortinet</category><category>CVE-2023-48788</category><category>RCE</category><category>FortiClient EMS</category><category>SQL Injection</category></item><item><title>Ivanti, Fortinet, and n8n Disclose Critical RCE and Auth Bypass Flaws</title><link>https://runtimerebel.com/blog/ivanti-fortinet-and-n8n-disclose-critical-rce-and-auth-bypass-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-fortinet-and-n8n-disclose-critical-rce-and-auth-bypass-flaws</guid><description>Ivanti, Fortinet, n8n, and SAP release urgent security patches for critical vulnerabilities including CVE-2026-5444 and CVE-2026-8043. Update systems now.</description><pubDate>Mon, 18 May 2026 13:23:34 GMT</pubDate><category>CVE-2026-8043</category><category>CVE-2026-5444</category><category>Ivanti</category><category>Fortinet</category><category>N8n</category><category>RCE</category></item><item><title>SAP CVE-2026-27681: Critical SQL Injection Vulnerability Patch Guidance</title><link>https://runtimerebel.com/blog/sap-cve-2026-27681-critical-sql-injection-vulnerability-patch-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/sap-cve-2026-27681-critical-sql-injection-vulnerability-patch-guidance</guid><description>April Patch Tuesday addresses a critical 9.9 CVSS SQL injection vulnerability in SAP Business Warehouse and updates for Microsoft, Adobe, and Fortinet.</description><pubDate>Wed, 15 Apr 2026 16:28:18 GMT</pubDate><category>CVE-2026-27681</category><category>SAP</category><category>Patch Tuesday</category><category>SQL Injection</category><category>Microsoft</category><category>Fortinet</category></item><item><title>CVE-2024-21762 and Ivanti Flaws: Edge Gateway Scanning Escalates</title><link>https://runtimerebel.com/blog/cve-2024-21762-and-ivanti-flaws-edge-gateway-scanning-escalates</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-21762-and-ivanti-flaws-edge-gateway-scanning-escalates</guid><description>Technical analysis of ongoing scanning activity targeting Ivanti and Fortinet SSL-VPN gateways. Learn to detect exploits and apply critical mitigations.</description><pubDate>Wed, 15 Apr 2026 08:41:41 GMT</pubDate><category>Ivanti</category><category>Fortinet</category><category>Ssl Vpn</category><category>CVE-2024-21762</category><category>CVE-2023-46805</category><category>RCE</category></item><item><title>CISA KEV Update: Fortinet FortiClient EMS CVE-2026-21643 Under Attack</title><link>https://runtimerebel.com/blog/cisa-kev-update-fortinet-forticlient-ems-cve-2026-21643-under-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-update-fortinet-forticlient-ems-cve-2026-21643-under-attack</guid><description>CISA adds six flaws to the KEV catalog, including a critical unauthenticated SQL injection in Fortinet FortiClient EMS (CVE-2026-21643). Patch immediately.</description><pubDate>Tue, 14 Apr 2026 08:40:46 GMT</pubDate><category>Fortinet</category><category>CVE-2026-21643</category><category>CISA KEV</category><category>SQL Injection</category><category>FortiClient EMS</category></item><item><title>CISA KEV Update: Exchange Server, Adobe, MS Windows Exploits</title><link>https://runtimerebel.com/blog/cisa-kev-update-exchange-server-adobe-ms-windows-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-update-exchange-server-adobe-ms-windows-exploits</guid><description>CISA adds seven vulnerabilities, including critical Microsoft Exchange Server deserialization, to its Known Exploited Vulnerabilities Catalog, urging immediate…</description><pubDate>Tue, 14 Apr 2026 00:47:03 GMT</pubDate><category>CVE-2012-1854</category><category>CVE-2020-9715</category><category>CVE-2023-21529</category><category>CVE-2023-36424</category><category>CVE-2025-60710</category><category>CVE-2026-21643</category><category>CVE-2026-34621</category><category>Microsoft Exchange Server</category><category>Adobe Acrobat</category><category>Microsoft Windows</category><category>Fortinet</category><category>CISA</category><category>KEV Catalog</category><category>Deserialization</category><category>Use After Free</category><category>SQL Injection</category></item><item><title>CVE-2026-35616: Fortinet FortiClient EMS Vulnerability — KEV Alert</title><link>https://runtimerebel.com/blog/cve-2026-35616-fortinet-forticlient-ems-vulnerability-kev-alert</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-35616-fortinet-forticlient-ems-vulnerability-kev-alert</guid><description>CISA adds CVE-2026-35616 affecting Fortinet FortiClient EMS to its Known Exploited Vulnerabilities catalog. Learn how to mitigate this access control flaw.</description><pubDate>Mon, 06 Apr 2026 16:23:16 GMT</pubDate><category>CVE-2026-35616</category><category>Fortinet</category><category>FortiClient EMS</category><category>KEV</category><category>Access Control</category></item><item><title>FortiClient EMS RCE via CVE-2023-48788 — Patch Guidance</title><link>https://runtimerebel.com/blog/forticlient-ems-rce-via-cve-2023-48788-patch-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/forticlient-ems-rce-via-cve-2023-48788-patch-guidance</guid><description>CISA mandates federal agencies patch the critical FortiClient EMS SQL injection flaw, CVE-2023-48788, which allows unauthenticated remote code execution.</description><pubDate>Mon, 06 Apr 2026 16:21:26 GMT</pubDate><category>CVE-2023-48788</category><category>Fortinet</category><category>CISA</category><category>RCE</category><category>SQL Injection</category></item><item><title>Chrome Zero-Day and Fortinet Exploits: Weekly Threat Intelligence</title><link>https://runtimerebel.com/blog/chrome-zero-day-and-fortinet-exploits-weekly-threat-intelligence</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-zero-day-and-fortinet-exploits-weekly-threat-intelligence</guid><description>Intelligence analysis of the latest Chrome zero-day, Fortinet vulnerabilities, and the Axios security breach, including technical remediation for SOC teams.</description><pubDate>Mon, 06 Apr 2026 16:20:58 GMT</pubDate><category>Google Chrome</category><category>Fortinet</category><category>Axios Hack</category><category>Paragon Spyware</category><category>Zero-Day</category></item><item><title>FortiClient EMS RCE via CVE-2026-35616 — Mitigation Guide</title><link>https://runtimerebel.com/blog/forticlient-ems-rce-via-cve-2026-35616-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/forticlient-ems-rce-via-cve-2026-35616-mitigation-guide</guid><description>Fortinet releases emergency patches for CVE-2026-35616, a critical SQL injection flaw in FortiClient EMS exploited to achieve unauthenticated RCE.</description><pubDate>Sun, 05 Apr 2026 20:12:25 GMT</pubDate><category>CVE-2026-35616</category><category>Fortinet</category><category>FortiClient EMS</category><category>RCE</category><category>Active Exploitation</category></item><item><title>CVE-2026-35616: Critical FortiClient EMS API Bypass Exploited</title><link>https://runtimerebel.com/blog/cve-2026-35616-critical-forticlient-ems-api-bypass-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-35616-critical-forticlient-ems-api-bypass-exploited</guid><description>Fortinet releases out-of-band patches for CVE-2026-35616, a critical API access bypass in FortiClient EMS enabling unauthenticated privilege escalation.</description><pubDate>Sun, 05 Apr 2026 08:18:00 GMT</pubDate><category>CVE-2026-35616</category><category>FortiClient EMS</category><category>Fortinet</category><category>Privilege Escalation</category></item><item><title>Fortinet FortiClient EMS Critical SQLi Flaw Under Active Exploitation</title><link>https://runtimerebel.com/blog/fortinet-forticlient-ems-critical-sqli-flaw-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortinet-forticlient-ems-critical-sqli-flaw-under-active-exploitation</guid><description>Critical SQL injection in FortiClient EMS allows unauthenticated remote code execution. Active exploitation detected, immediate patching required.</description><pubDate>Tue, 31 Mar 2026 12:31:11 GMT</pubDate><category>Fortinet</category><category>FortiClient EMS</category><category>SQL Injection</category><category>RCE</category><category>Exploitation</category></item><item><title>CVE-2023-48788: FortiClient EMS RCE via SQL Injection Exploit</title><link>https://runtimerebel.com/blog/cve-2023-48788-forticlient-ems-rce-via-sql-injection-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-48788-forticlient-ems-rce-via-sql-injection-exploit</guid><description>Exploitation of a critical RCE vulnerability (CVE-2023-48788) in Fortinet FortiClient EMS has been confirmed. Learn how to detect and mitigate this threat.</description><pubDate>Mon, 30 Mar 2026 08:40:09 GMT</pubDate><category>CVE-2023-48788</category><category>Fortinet</category><category>FortiClient EMS</category><category>RCE</category><category>SQL Injection</category></item><item><title>Siemens RUGGEDCOM APE1808 Critical Authentication Bypass — Patch Now</title><link>https://runtimerebel.com/blog/siemens-ruggedcom-ape1808-critical-authentication-bypass-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/siemens-ruggedcom-ape1808-critical-authentication-bypass-patch-now</guid><description>Security alert for Siemens RUGGEDCOM APE1808. Multiple vulnerabilities, including a 9.8 CVSS authentication bypass, affect ICS environments. Patch immediately.</description><pubDate>Thu, 12 Mar 2026 20:16:11 GMT</pubDate><category>CVE-2026-24858</category><category>Siemens</category><category>RUGGEDCOM</category><category>Fortinet</category><category>Industrial Control Systems</category><category>ICS Security</category></item><item><title>Fortinet, Ivanti, and Intel Patch High-Severity RCE Vulnerabilities</title><link>https://runtimerebel.com/blog/fortinet-ivanti-and-intel-patch-high-severity-rce-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortinet-ivanti-and-intel-patch-high-severity-rce-vulnerabilities</guid><description>Fortinet, Ivanti, and Intel have issued patches for high-severity vulnerabilities in FortiClient, ICS gateways, and various hardware drivers.</description><pubDate>Wed, 11 Mar 2026 12:20:19 GMT</pubDate><category>CVE-2024-36513</category><category>CVE-2024-37375</category><category>Fortinet</category><category>Ivanti</category><category>Intel</category><category>RCE</category></item><item><title>FortiGate NGFW Exploitation Leads to Service Account Credential Theft</title><link>https://runtimerebel.com/blog/fortigate-ngfw-exploitation-leads-to-service-account-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortigate-ngfw-exploitation-leads-to-service-account-credential-theft</guid><description>Threat actors are exploiting FortiGate devices to extract configuration files and steal service account credentials, facilitating lateral movement in networks.</description><pubDate>Tue, 10 Mar 2026 20:12:12 GMT</pubDate><category>Fortinet</category><category>FortiGate</category><category>Ngfw</category><category>Credential Theft</category><category>Fortios</category></item><item><title>CyberStrikeAI Exploitation: AI Tools Targeting Fortinet Firewalls</title><link>https://runtimerebel.com/blog/cyberstrikeai-exploitation-ai-tools-targeting-fortinet-firewalls</link><guid isPermaLink="true">https://runtimerebel.com/blog/cyberstrikeai-exploitation-ai-tools-targeting-fortinet-firewalls</guid><description>Threat actors are repurposing CyberStrikeAI to automate reconnaissance and exploit critical vulnerabilities in Fortinet FortiGate firewalls and edge devices.</description><pubDate>Tue, 03 Mar 2026 00:36:03 GMT</pubDate><category>CyberStrikeAI</category><category>Fortinet</category><category>CVE-2024-21762</category><category>AI Powered Attacks</category><category>Reconnaissance</category></item><item><title>Automated Exploitation Analysis: AI-Assisted Breach of FortiGate Infrastructure</title><link>https://runtimerebel.com/blog/automated-exploitation-analysis-ai-assisted-breach-of-fortigate-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/automated-exploitation-analysis-ai-assisted-breach-of-fortigate-infrastructure</guid><description>Amazon threat intelligence identifies a high-velocity campaign leveraging LLM automation to compromise over 600 FortiGate firewalls across 55 countries in a five-week…</description><pubDate>Mon, 23 Feb 2026 05:33:11 GMT</pubDate><category>Fortinet</category><category>AI Threats</category><category>Exploitation</category><category>Automation</category><category>Russian Nexus</category></item></channel></rss>